Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
142
Current result set after filter and search.
Exploited Flagged
128
Rows with a non-empty exploitation signal.
Distinct CWE
9
Unique weakness classes in this view.
Modules
74
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-20: Improper Input Validation Clear filters
Release Month
August 2023
2 CVE | last update 1 day(s) ago
Release 2023-08-08 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-35377
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-08-08 No
Reported By
CVE-2023-35376
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-08-08 No
Reported By
Release Month
July 2023
7 CVE | last update 1 day(s) ago
Release 2023-07-11 Patch Tuesday Count 7
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-35367
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
wkai with Codesafe Team of Legendsec at QI-ANXIN Group
CVE-2023-35366
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
wkai with Codesafe Team of Legendsec at QI-ANXIN Group
CVE-2023-35365
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
wkai with Codesafe Team of Legendsec at QI-ANXIN Group
CVE-2023-32037
Windows Layer-2 Bridge Network Driver
Exploitation Less Likely
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-07-11 No
Reported By
greenbamboo
CVE-2023-35303
USB Audio Class System Driver
Exploitation Less Likely
USB Audio Class System Driver Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
B1aN
CVE-2023-35306
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-07-11 No
Reported By
kap0k
CVE-2023-32057
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-07-11 No
Release Month
June 2023
4 CVE | last update 1 day(s) ago
Release 2023-06-13 Patch Tuesday Count 4
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-32015
Windows Pragmatic General Multicast (PGM)
Exploitation Less Likely
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
Anonymous
CVE-2023-29371
Windows GDI
Exploitation More Likely
Windows GDI Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
Keqi Hu
CVE-2023-24937
Windows CryptoAPI
Exploitation Less Likely
Windows CryptoAPI Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
Kevin Jones with GitHub
CVE-2023-29359
GDI
Exploitation More Likely
GDI Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
Marcin Wiazowski working with Trend Micro Zero Day Initiative
Release Month
April 2023
6 CVE | last update 1 day(s) ago
Release 2023-04-11 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-28274
Windows Win32k
Exploitation More Likely
Windows Win32k Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
2023-04-11 No
Reported By
Anonymous
CVE-2023-28291
Raw Image Extension
Exploitation Less Likely
Raw Image Extension Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-04-11 No
Reported By
ze0r with venustech ADLAB
CVE-2023-28304
Microsoft ODBC and OLE DB
Exploitation Less Likely
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
2023-04-11 No
Reported By
CVE-2023-23375
Microsoft ODBC and OLE DB
Exploitation Less Likely
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
2023-04-11 No
Reported By
CVE-2023-28302
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-04-11 No
Reported By
Haifei Li with Check Point Research
Wayne Low of Fortinet's FortiGuard Lab
Jarvis_1oop
Bing Sun with Trellix Advanced Research Center
CVE-2023-21554
Microsoft Message Queuing (MSMQ)
Exploitation More Likely
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-04-11 No
Release Month
March 2023
6 CVE | last update 1 day(s) ago
Release 2023-03-14 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-23419
Windows Resilient File System (ReFS)
Exploitation Less Likely
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
CVE-2023-23416
Windows Cryptographic Services
Exploitation More Likely
Windows Cryptographic Services Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
CVE-2023-24866
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Reported By
kap0k
CVE-2023-24865
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Reported By
kap0k
CVE-2023-24856
Microsoft PostScript and PCL6 Class Printer Driver
Exploitation Less Likely
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Reported By
kap0k
CVE-2023-23409
Client Server Run-Time Subsystem (CSRSS)
Exploitation Less Likely
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-03-14 No
Release Month
February 2023
2 CVE | last update 1 day(s) ago
Release 2023-02-14 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21818
Windows Secure Channel
Exploitation More Likely
Windows Secure Channel Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-02-14 No
Reported By
Jason Fisher
Polar Bear
Andrei Popov
CVE-2023-21816
Windows Active Directory Domain Services API
Exploitation Less Likely
Windows Active Directory Domain Services API Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-02-14 No
Reported By
bee13oy with Cyber Kunlun Lab
Release Month
January 2023
6 CVE | last update 1 day(s) ago
Release 2023-01-10 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21767
Windows Overlay Filter
Exploitation Less Likely
Windows Overlay Filter Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
CVE-2023-21749
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Mateusz Jurczyk of Google Project Zero
CVE-2023-21558
Windows Error Reporting Service
Exploitation Less Likely
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Anonymous
CVE-2023-21559
Windows Cryptographic
Exploitation Less Likely
Windows Cryptographic Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-01-10 No
CVE-2023-21550
Windows Cryptographic
Exploitation Less Likely
Windows Cryptographic Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE)
CVE-2023-21540
Windows Cryptographic
Exploitation Less Likely
Windows Cryptographic Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE)
Release Month
August 2021
2 CVE | last update 1 day(s) ago
Release 2021-08-25 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-22931
Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to
No latest release note
Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to Remote Code Execution XSS Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2021-08-25 - -
Release 2021-08-14 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3580
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and
No latest release note
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-08-14 - -
Release Month
July 2021
2 CVE | last update 1 day(s) ago
Release 2021-07-30 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2015-4646
(1) unsquash-1.c (2) unsquash-2.c (3) unsquash-3.c and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a
No latest release note
(1) unsquash-1.c (2) unsquash-2.c (3) unsquash-3.c and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-07-30 - -
Release 2021-07-16 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-14992
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0 1.10.3 17.03.0 17.03.1 17.03.2 17.06.0 17.06.1 17.06.2 17.09.0 and earlier allows a remote attacker to cause a
No latest release note
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0 1.10.3 17.03.0 17.03.1 17.03.2 17.06.0 17.06.1 17.06.2 17.09.0 and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload aka gzip bombing.
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2021-07-16 - -
Release Month
June 2021
3 CVE | last update 1 day(s) ago
Release 2021-06-06 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-1000168
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to
No latest release note
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
CVE-2018-7162
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a
No latest release note
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
CVE-2018-7161
All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a
No latest release note
All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
Release Month
October 2020
1 CVE | last update 1 day(s) ago
Release 2020-10-17 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-25643
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a
No latest release note
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
2020-10-17 - -
Release Month
August 2020
1 CVE | last update 1 day(s) ago
Release 2020-08-18 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2012-6687
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a
No latest release note
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
No CVSS vector published
2020-08-18 - -
Prev Page 3 / 3 | rows 101-142 of 142